SB2016091243 - Resource management error in wireshark (Alpine package)
Published: September 12, 2016
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Resource management error (CVE-ID: CVE-2016-6508)
The vulnerability allows a remote non-authenticated attacker to perform a denial of service (DoS) attack.
epan/dissectors/packet-rlc.c in the RLC dissector in Wireshark 1.12.x before 1.12.13 and 2.x before 2.0.5 uses an incorrect integer data type, which allows remote attackers to cause a denial of service (large loop) via a crafted packet.
Remediation
Install update from vendor's website.
References
- https://git.alpinelinux.org/aports/commit/?id=012e5b8ddaa5ad3353e0df651fd6b2f2097705ab
- https://git.alpinelinux.org/aports/commit/?id=a3941a00036014165b8ba5ecdf3b74264d05f3c4
- https://git.alpinelinux.org/aports/commit/?id=71e23d72a21db07cd80913b497c92f3b20585c2c
- https://git.alpinelinux.org/aports/commit/?id=f69acd7283a989adcfb4cccf1ce1648af851f990
- https://git.alpinelinux.org/aports/commit/?id=c50651068f78da271552efce20a0399ab88985f5
- https://git.alpinelinux.org/aports/commit/?id=e1d225fddc4d9dbb88b2f6f5bbcb4b00d04f5012